2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31176 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31174 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31172 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31171 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31165 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31164 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31160 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31159 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-41240 | MEDIUM | 6.1 | 0.3% | Apr 23, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an incons... |
| CVE-2026-41239 | MEDIUM | 6.8 | 0.2% | Apr 23, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior t... |
| CVE-2026-41238 | MEDIUM | 6.9 | 0.2% | Apr 23, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulne... |
| CVE-2026-39087 | MEDIUM | 6.4 | 0.4% | Apr 23, 2026 | ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs. |
| CVE-2026-31531 | MEDIUM | 5.5 | 0.2% | Apr 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dynamically in rtm_get_... |
| CVE-2026-28040 | MEDIUM | 6.5 | 0.2% | Apr 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Ta... |
| CVE-2026-4106 | MEDIUM | 5.3 | 0.7% | Apr 23, 2026 | The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P... |
| CVE-2026-41990 | MEDIUM | 4 | 0.2% | Apr 23, 2026 | Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack... |
| CVE-2026-41989 | MEDIUM | 6.7 | 0.2% | Apr 23, 2026 | Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext ... |
| CVE-2026-41233 | MEDIUM | 5.4 | 0.3% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet... |
| CVE-2026-41232 | MEDIUM | 5 | 0.2% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner... |
| CVE-2026-40529 | MEDIUM | 5.1 | 0.2% | Apr 23, 2026 | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be ... |
| CVE-2026-3361 | MEDIUM | 6.4 | 0.2% | Apr 23, 2026 | The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta ... |
| CVE-2026-3007 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr... |
| CVE-2026-2951 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-41243 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf... |
| CVE-2026-41182 | MEDIUM | 5.3 | 0.2% | Apr 23, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now